Dependency Confusion on npm: Recon via postinstall Hooks Threatens Windows Dev Environments
Microsoft Threat Intelligence disclosed on May 29, 2026 that a fresh wave of dependency confusion attacks targeting the npm ecosystem leveraged malicious postinstall scripts to conduct reconnaissance...